CVE-2009-0258

The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is not properly handled by the command-line indexer.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
typo3typo3
4.0
typo3typo3
4.0.1
typo3typo3
4.0.2
typo3typo3
4.0.3
typo3typo3
4.0.4
typo3typo3
4.0.5
typo3typo3
4.0.6
typo3typo3
4.0.7
typo3typo3
4.0.8
typo3typo3
4.0.9
typo3typo3
4.1.0
typo3typo3
4.1.0:beta1
typo3typo3
4.1.0:rc1
typo3typo3
4.1.1
typo3typo3
4.1.2
typo3typo3
4.1.3
typo3typo3
4.1.4
typo3typo3
4.1.5
typo3typo3
4.1.6
typo3typo3
4.1.7
typo3typo3
4.2.0
typo3typo3
4.2.1
typo3typo3
4.2.2
typo3typo3
4.2.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
typo3-src
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
ignored
hardy
ignored
gutsy
ignored
dapper
ignored